DSA-2023-429: Security Update for Dell 16G PowerEdge Server BIOS for a Debug Code Security Vulnerability

요약: Dell 16G PowerEdge Server BIOS remediation is available for a Debug Code Security Vulnerability that could be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

High

세부 정보

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-44297 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. 7.1 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-44298 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. 3.6 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-44297 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service. 7.1 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-44298 Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service. 3.6 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:LThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge R660 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660/drivers
PowerEdge R760 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760/drivers
PowerEdge C6620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-c6620/drivers
PowerEdge MX760c BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-mx760c/drivers
PowerEdge R860 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r860/drivers
PowerEdge R960 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r960/drivers
PowerEdge HS5610 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5610/drivers
PowerEdge HS5620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5620/drivers
PowerEdge R660xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660xs/drivers
PowerEdge R760xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xs/drivers
PowerEdge R760xd2 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xd2/drivers
PowerEdge T560 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-t560/drivers
PowerEdge R760xa BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xa/drivers
Product Software/Firmware Affected Versions Remediated Versions Link
PowerEdge R660 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660/drivers
PowerEdge R760 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760/drivers
PowerEdge C6620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-c6620/drivers
PowerEdge MX760c BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-mx760c/drivers
PowerEdge R860 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r860/drivers
PowerEdge R960 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r960/drivers
PowerEdge HS5610 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5610/drivers
PowerEdge HS5620 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-hs5620/drivers
PowerEdge R660xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r660xs/drivers
PowerEdge R760xs BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xs/drivers
PowerEdge R760xd2 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xd2/drivers
PowerEdge T560 BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-t560/drivers
PowerEdge R760xa BIOS Version 1.4.4 Version 1.5.6 or later https://www.dell.com/support/home/product-support/product/poweredge-r760xa/drivers
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.

해결 방법 및 완화 방안

None

개정 내역

RevisionDateDescription
1.02023-12-04Initial release
2.02024-06-13Updated for enhanced presentation with no changes to content

관련 정보

해당 제품

PowerEdge C6620, PowerEdge HS5610, PowerEdge HS5620, PowerEdge MX760c, PowerEdge R660, PowerEdge R660xs, PowerEdge R760, PowerEdge R760XA, PowerEdge R760xd2, PowerEdge R760xs, PowerEdge R860, PowerEdge R960, PowerEdge T560
문서 속성
문서 번호: 000220047
문서 유형: Dell Security Advisory
마지막 수정 시간: 13 6월 2024
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.